Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-43035
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-43035

2022-10-1900:00:00
ubuntu.com
ubuntu.com
19
cve-2022-43035
bento4 v1.6.0-639
heap buffer overflow
denial of service
mp42aac
kodi-inputstream-adaptive
embedded copy
unix

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.1%

An issue was discovered in Bento4 v1.6.0-639. There is a
heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp,
leading to a Denial of Service (DoS), as demonstrated by mp42aac.

Notes

Author Note
alexmurray kodi-inputstream-adaptive contains an embedded copy of bento4

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.1%

Related for UB:CVE-2022-43035